All done:
"Silent Runners.vbs", revision 36,
http://www.silentrunners.org/Operating System: Windows 2000
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"internat.exe" = "internat.exe" [MS]
"wymrvfy" = "c:\winnt\ohrxdnu.exe" [file not found]
"hesakcb" = "c:\winnt\ohrxdnu.exe" [file not found]
"ydvxcka" = "c:\winnt\ohrxdnu.exe" [file not found]
"bspjlog" = "c:\winnt\ohrxdnu.exe" [file not found]
"avqdivq" = "c:\winnt\ohrxdnu.exe" [file not found]
"hkokhoj" = "c:\winnt\ohrxdnu.exe" [file not found]
"ywpenwu" = "c:\winnt\ohrxdnu.exe" [file not found]
"sujqtiv" = "c:\winnt\ohrxdnu.exe" [file not found]
"eqdolgd" = "c:\winnt\ohrxdnu.exe" [file not found]
"kkuqlgl" = "c:\winnt\ohrxdnu.exe" [file not found]
"ubmndea" = "c:\winnt\ohrxdnu.exe" [file not found]
"oiqdlto" = "c:\winnt\ohrxdnu.exe" [file not found]
"erfpphm" = "c:\winnt\ohrxdnu.exe" [file not found]
"mpmgqvd" = "c:\winnt\ohrxdnu.exe" [file not found]
"wjxowql" = "c:\winnt\ohrxdnu.exe" [file not found]
"umyagtg" = "c:\winnt\ohrxdnu.exe" [file not found]
"fcbmsce" = "c:\winnt\ohrxdnu.exe" [file not found]
"pakynre" = "c:\winnt\ohrxdnu.exe" [file not found]
"qvuufop" = "c:\winnt\ohrxdnu.exe" [file not found]
"mxmshow" = "c:\winnt\ohrxdnu.exe" [file not found]
"nptykyg" = "c:\winnt\ohrxdnu.exe" [file not found]
"icmvgda" = "c:\winnt\ohrxdnu.exe" [file not found]
"caqmvwi" = "c:\winnt\kadtfeo.exe" [file not found]
"ikihvdc" = "c:\winnt\kadtfeo.exe" [file not found]
"hewqaos" = "c:\winnt\kadtfeo.exe" [file not found]
"pswrdvo" = "c:\winnt\kadtfeo.exe" [file not found]
"snhfutt" = "c:\winnt\kadtfeo.exe" [file not found]
"jjxgtvm" = "c:\winnt\kadtfeo.exe" [file not found]
"vtpdses" = "c:\winnt\kadtfeo.exe" [file not found]
"bsgjfye" = "c:\winnt\kadtfeo.exe" [file not found]
"udqxvbl" = "c:\winnt\kadtfeo.exe" [file not found]
"hitasut" = "c:\winnt\cnurihq.exe" [file not found]
"jmesujl" = "c:\winnt\cnurihq.exe" [file not found]
"jgutffg" = "c:\winnt\cnurihq.exe" [file not found]
"teltnsp" = "c:\winnt\cnurihq.exe" [file not found]
"owurqis" = "c:\winnt\cnurihq.exe" [file not found]
"qusxoeo" = "c:\winnt\cnurihq.exe" [file not found]
"hkrttta" = "c:\winnt\cnurihq.exe" [file not found]
"qskudot" = "c:\winnt\cnurihq.exe" [file not found]
"pbjitog" = "c:\winnt\cnurihq.exe" [file not found]
"midmbwv" = "c:\winnt\cnurihq.exe" [file not found]
"fhrfkxp" = "c:\winnt\cnurihq.exe" [file not found]
"oaiaedw" = "c:\winnt\cnurihq.exe" [file not found]
"vvdlmjc" = "c:\winnt\cnurihq.exe" [file not found]
"rnvwyba" = "c:\winnt\cnurihq.exe" [file not found]
"ojmpnwk" = "c:\winnt\cnurihq.exe" [file not found]
"hbsfrhw" = "c:\winnt\cnurihq.exe" [file not found]
"gggggxo" = "c:\winnt\cnurihq.exe" [file not found]
"huqcsgj" = "c:\winnt\cnurihq.exe" [file not found]
"irrccpu" = "c:\winnt\cnurihq.exe" [file not found]
"uwjvnln" = "c:\winnt\cnurihq.exe" [file not found]
"epsrjti" = "c:\winnt\mwiswfo.exe" [file not found]
"ffihdnc" = "c:\winnt\mwiswfo.exe" [file not found]
"oohanrj" = "c:\winnt\mwiswfo.exe" [file not found]
"gisvghe" = "c:\winnt\mwiswfo.exe" [file not found]
"jusdyqg" = "c:\winnt\mwiswfo.exe" [file not found]
"ukohfei" = "c:\winnt\mwiswfo.exe" [file not found]
"tupyrsn" = "c:\winnt\mwiswfo.exe" [file not found]
"drasegk" = "c:\winnt\mwiswfo.exe" [file not found]
"tradkou" = "c:\winnt\mwiswfo.exe" [file not found]
"yccsets" = "c:\winnt\mwiswfo.exe" [file not found]
"iwlbnvs" = "c:\winnt\mwiswfo.exe" [file not found]
"vxslbei" = "c:\winnt\mwiswfo.exe" [file not found]
"bitkaqt" = "c:\winnt\mwiswfo.exe" [file not found]
"bwuykvd" = "c:\winnt\mwiswfo.exe" [file not found]
"cfkixgk" = "c:\winnt\mwiswfo.exe" [file not found]
"xsqqpoq" = "c:\winnt\mwiswfo.exe" [file not found]
"thbfpfl" = "c:\winnt\mwiswfo.exe" [file not found]
"kibuwdc" = "c:\winnt\mwiswfo.exe" [file not found]
"fsqowsf" = "c:\winnt\mwiswfo.exe" [file not found]
"evedfyu" = "c:\winnt\mwiswfo.exe" [file not found]
"jlyotdv" = "c:\winnt\mwiswfo.exe" [file not found]
"efvahem" = "c:\winnt\mwiswfo.exe" [file not found]
"owccmuo" = "c:\winnt\mwiswfo.exe" [file not found]
"miivuet" = "c:\winnt\mwiswfo.exe" [file not found]
"wkekaan" = "c:\winnt\mwiswfo.exe" [file not found]
"qgssfdo" = "c:\winnt\mwiswfo.exe" [file not found]
"vcevdfm" = "c:\winnt\mwiswfo.exe" [file not found]
"nxptycu" = "c:\winnt\mwiswfo.exe" [file not found]
"oqsbtmi" = "c:\winnt\mwiswfo.exe" [file not found]
"ppkcjsk" = "c:\winnt\mwiswfo.exe" [file not found]
"qqvqiws" = "c:\winnt\mwiswfo.exe" [file not found]
"hkqefaf" = "c:\winnt\mwiswfo.exe" [file not found]
"dxeoely" = "c:\winnt\mwiswfo.exe" [file not found]
"pnitcho" = "c:\winnt\mwiswfo.exe" [file not found]
"arrgjre" = "c:\winnt\mwiswfo.exe" [file not found]
"ealmrwc" = "c:\winnt\mwiswfo.exe" [file not found]
"cpbglvh" = "c:\winnt\mwiswfo.exe" [file not found]
"sderaly" = "c:\winnt\mwiswfo.exe" [file not found]
"ixuotoq" = "c:\winnt\mwiswfo.exe" [file not found]
"gxxvlnf" = "c:\winnt\mwiswfo.exe" [file not found]
"pdocqpn" = "c:\winnt\mwiswfo.exe" [file not found]
"jdrqpmh" = "c:\winnt\mwiswfo.exe" [file not found]
"irldsix" = "c:\winnt\mwiswfo.exe" [file not found]
"evpbhwi" = "c:\winnt\mwiswfo.exe" [file not found]
"kmukorg" = "c:\winnt\mwiswfo.exe" [file not found]
"yqwjghr" = "c:\winnt\mwiswfo.exe" [file not found]
"tdkibxe" = "c:\winnt\mwiswfo.exe" [file not found]
"uqwcupk" = "c:\winnt\mwiswfo.exe" [file not found]
"fxupxlb" = "c:\winnt\mwiswfo.exe" [file not found]
"ffryjpl" = "c:\winnt\mwiswfo.exe" [file not found]
"aamwhmn" = "c:\winnt\mwiswfo.exe" [file not found]
"vagjdka" = "c:\winnt\mwiswfo.exe" [file not found]
"llqqdhj" = "c:\winnt\mwiswfo.exe" [file not found]
"afcwccw" = "c:\winnt\imujmni.exe" [file not found]
"rpekvgf" = "c:\winnt\imujmni.exe" [file not found]
"oihmkve" = "c:\winnt\imujmni.exe" [file not found]
"gnhpayx" = "c:\winnt\imujmni.exe" [file not found]
"whlinpb" = "c:\winnt\imujmni.exe" [file not found]
"dsfsofp" = "c:\winnt\imujmni.exe" [file not found]
"hijxopg" = "c:\winnt\imujmni.exe" [file not found]
"oscuxms" = "c:\winnt\imujmni.exe" [file not found]
"lpihaxe" = "c:\winnt\imujmni.exe" [file not found]
"vysgsjv" = "c:\winnt\imujmni.exe" [file not found]
"nmsgloc" = "c:\winnt\imujmni.exe" [file not found]
"qwobeto" = "c:\winnt\imujmni.exe" [file not found]
"bhjdena" = "c:\winnt\imujmni.exe" [file not found]
"eirpatk" = "c:\winnt\imujmni.exe" [file not found]
"mrbqxia" = "c:\winnt\imujmni.exe" [file not found]
"hxkiejj" = "c:\winnt\imujmni.exe" [file not found]
"pirjqon" = "c:\winnt\imujmni.exe" [file not found]
"mdhfpkf" = "c:\winnt\imujmni.exe" [file not found]
"wutvhqw" = "c:\winnt\imujmni.exe" [file not found]
"hoowwkq" = "c:\winnt\imujmni.exe" [file not found]
"eiwodod" = "c:\winnt\imujmni.exe" [file not found]
"qhiboty" = "c:\winnt\imujmni.exe" [file not found]
"inslqeq" = "c:\winnt\imujmni.exe" [file not found]
"jgwkkwj" = "c:\winnt\imujmni.exe" [file not found]
"orvtosm" = "c:\winnt\imujmni.exe" [file not found]
"wbmhbtg" = "c:\winnt\imujmni.exe" [file not found]
"chrohsl" = "c:\winnt\imujmni.exe" [file not found]
"amuklml" = "c:\winnt\imujmni.exe" [file not found]
"rflurmo" = "c:\winnt\imujmni.exe" [file not found]
"vgfgnjm" = "c:\winnt\imujmni.exe" [file not found]
"hlrhbao" = "c:\winnt\imujmni.exe" [file not found]
"wfsdpsf" = "c:\winnt\imujmni.exe" [file not found]
"xmcoxwd" = "c:\winnt\imujmni.exe" [file not found]
"jdwxouv" = "c:\winnt\imujmni.exe" [file not found]
"xeemdag" = "c:\winnt\imujmni.exe" [file not found]
"khkiefh" = "c:\winnt\imujmni.exe" [file not found]
"yvtompe" = "c:\winnt\imujmni.exe" [file not found]
"tbcflen" = "c:\winnt\imujmni.exe" [file not found]
"ysulbxi" = "c:\winnt\imujmni.exe" [file not found]
"tpamgwd" = "c:\winnt\imujmni.exe" [file not found]
"uoohbgi" = "c:\winnt\imujmni.exe" [file not found]
"oboluvm" = "c:\winnt\imujmni.exe" [file not found]
"amkqjqn" = "c:\winnt\imujmni.exe" [file not found]
"ygxgiid" = "c:\winnt\imujmni.exe" [file not found]
"fbcwgnt" = "c:\winnt\imujmni.exe" [file not found]
"gwdvyel" = "c:\winnt\imujmni.exe" [file not found]
"ulmnxsv" = "c:\winnt\imujmni.exe" [file not found]
"uiodpbx" = "c:\winnt\imujmni.exe" [file not found]
"jeotdpd" = "c:\winnt\imujmni.exe" [file not found]
"oryhxba" = "c:\winnt\imujmni.exe" [file not found]
"qhlpjcl" = "c:\winnt\imujmni.exe" [file not found]
"ihxynbh" = "c:\winnt\imujmni.exe" [file not found]
"ypfgilf" = "c:\winnt\imujmni.exe" [file not found]
"denqjrj" = "c:\winnt\imujmni.exe" [file not found]
"pcafyfo" = "c:\winnt\imujmni.exe" [file not found]
"gfrqsgq" = "c:\winnt\imujmni.exe" [file not found]
"njqhyln" = "c:\winnt\imujmni.exe" [file not found]
"cgjumje" = "c:\winnt\imujmni.exe" [file not found]
"ljdsurf" = "c:\winnt\imujmni.exe" [file not found]
"kwrxybb" = "c:\winnt\imujmni.exe" [file not found]
"yaxioqp" = "c:\winnt\imujmni.exe" [file not found]
"mlkbmhs" = "c:\winnt\imujmni.exe" [file not found]
"kysmeto" = "c:\winnt\imujmni.exe" [file not found]
"oiqbvwd" = "c:\winnt\imujmni.exe" [file not found]
"rntgpqb" = "c:\winnt\imujmni.exe" [file not found]
"qvrixmm" = "c:\winnt\imujmni.exe" [file not found]
"ajmakbk" = "c:\winnt\imujmni.exe" [file not found]
"paavjfn" = "c:\winnt\imujmni.exe" [file not found]
"axeuyjp" = "c:\winnt\bghxjvw.exe" [file not found]
"wpjixev" = "c:\winnt\bghxjvw.exe" [file not found]
"pnwcjom" = "c:\winnt\bghxjvw.exe" [file not found]
"iviavgl" = "c:\winnt\bghxjvw.exe" [file not found]
"ramibwu" = "c:\winnt\bghxjvw.exe" [file not found]
"oxrebmb" = "c:\winnt\bghxjvw.exe" [file not found]
"osonrdl" = "c:\winnt\bghxjvw.exe" [file not found]
"ajpcfpt" = "c:\winnt\bghxjvw.exe" [file not found]
"nbbonej" = "c:\winnt\bghxjvw.exe" [file not found]
"shyrsia" = "c:\winnt\bghxjvw.exe" [file not found]
"ayfgydw" = "c:\winnt\bghxjvw.exe" [file not found]
"shvmuhe" = "c:\winnt\bghxjvw.exe" [file not found]
"ixdtnen" = "c:\winnt\bghxjvw.exe" [file not found]
"njectjw" = "c:\winnt\bghxjvw.exe" [file not found]
"hfvlbjo" = "c:\winnt\bghxjvw.exe" [file not found]
"khhtxlj" = "c:\winnt\bghxjvw.exe" [file not found]
"ramyspf" = "c:\winnt\bghxjvw.exe" [file not found]
"jsjvfef" = "c:\winnt\bghxjvw.exe" [file not found]
"yjfdygd" = "c:\winnt\bghxjvw.exe" [file not found]
"ytlsqwl" = "c:\winnt\bghxjvw.exe" [file not found]
"lrvctym" = "c:\winnt\bghxjvw.exe" [file not found]
"ptacsln" = "c:\winnt\bghxjvw.exe" [file not found]
"wxhtffd" = "c:\winnt\bghxjvw.exe" [file not found]
"ixkggsa" = "c:\winnt\bghxjvw.exe" [file not found]
"eohpqwk" = "c:\winnt\bghxjvw.exe" [file not found]
"gvvhbqu" = "c:\winnt\bghxjvw.exe" [file not found]
"udayxsp" = "c:\winnt\bghxjvw.exe" [file not found]
"dnmsbcw" = "c:\winnt\bghxjvw.exe" [file not found]
"cemsnpb" = "c:\winnt\bghxjvw.exe" [file not found]
"yxnxslo" = "c:\winnt\bqeqaso.exe" [file not found]
"hrggukd" = "c:\winnt\bqeqaso.exe" [file not found]
"dhgwqyp" = "c:\winnt\bqeqaso.exe" [file not found]
"fvasaid" = "c:\winnt\bqeqaso.exe" [file not found]
"hnkqnsd" = "c:\winnt\bqeqaso.exe" [file not found]
"rknevxu" = "c:\winnt\bqeqaso.exe" [file not found]
"nftagqo" = "c:\winnt\bqeqaso.exe" [file not found]
"iiddptl" = "c:\winnt\bqeqaso.exe" [file not found]
"cyefhug" = "c:\winnt\bqeqaso.exe" [file not found]
"nccemra" = "c:\winnt\bqeqaso.exe" [file not found]
"lxnrooy" = "c:\winnt\bqeqaso.exe" [file not found]
"fmcwfkq" = "c:\winnt\bqeqaso.exe" [file not found]
"enqkyeq" = "c:\winnt\bqeqaso.exe" [file not found]
"fjekmkd" = "c:\winnt\bqeqaso.exe" [file not found]
"lwqcotb" = "c:\winnt\bqeqaso.exe" [file not found]
"uqbcovj" = "c:\winnt\bqeqaso.exe" [file not found]
"mgxsvch" = "c:\winnt\bqeqaso.exe" [file not found]
"cvuqaey" = "c:\winnt\bqeqaso.exe" [file not found]
"orvetwg" = "c:\winnt\bqeqaso.exe" [file not found]
"sjudger" = "c:\winnt\bqeqaso.exe" [file not found]
"sjpsouo" = "c:\winnt\bqeqaso.exe" [file not found]
"dtqflrv" = "c:\winnt\umetjwa.exe" [file not found]
"qqpiptd" = "c:\winnt\wbednct.exe" [file not found]
"fvimgni" = "c:\winnt\ejounne.exe" [file not found]
"dfrkged" = "c:\winnt\umetjwa.exe" [file not found]
"djhtbnv" = "c:\winnt\wbednct.exe" [file not found]
"ucjnhnx" = "c:\winnt\ejounne.exe" [file not found]
"qqvrspj" = "c:\winnt\wbednct.exe" [file not found]
"rkkubkc" = "c:\winnt\umetjwa.exe" [file not found]
"rehlsww" = "c:\winnt\ejounne.exe" [file not found]
"nmfhyhl" = "c:\winnt\wbednct.exe" [file not found]
"rlschev" = "c:\winnt\umetjwa.exe" [file not found]
"krfsrhy" = "c:\winnt\wbednct.exe" [file not found]
"xcluqra" = "c:\winnt\umetjwa.exe" [file not found]
"xlwmeij" = "c:\winnt\wbednct.exe" [file not found]
"jgrsahx" = "c:\winnt\umetjwa.exe" [file not found]
"qjfpjbr" = "c:\winnt\wbednct.exe" [file not found]
"iaylofm" = "c:\winnt\umetjwa.exe" [file not found]
"sgsfqaw" = "c:\winnt\vixwkwk.exe" [file not found]
"rjeniur" = "c:\winnt\vixwkwk.exe" [file not found]
"plbiyiv" = "c:\winnt\vixwkwk.exe" [file not found]
"aejqtjp" = "c:\winnt\vixwkwk.exe" [file not found]
"knneiyb" = "c:\winnt\vixwkwk.exe" [file not found]
"fmyeurc" = "c:\winnt\vixwkwk.exe" [file not found]
"dpyujba" = "c:\winnt\vixwkwk.exe" [file not found]
"jhnbqus" = "c:\winnt\vixwkwk.exe" [file not found]
"filddik" = "c:\winnt\vixwkwk.exe" [file not found]
"ayelfgb" = "c:\winnt\vixwkwk.exe" [file not found]
"tqutdfw" = "c:\winnt\vixwkwk.exe" [file not found]
"iygbtor" = "c:\winnt\vixwkwk.exe" [file not found]
"lluvtqb" = "c:\winnt\vixwkwk.exe" [file not found]
"nycaakt" = "c:\winnt\vixwkwk.exe" [file not found]
"gmouinj" = "c:\winnt\vixwkwk.exe" [file not found]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"Synchronization Manager" = "mobsync.exe /logon" [MS]
"ccApp" = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" ["Symantec Corporation"]
"URLLSTCK.exe" = "C:\Program Files\Norton Internet Security\UrlLstCk.exe" ["Symantec Corporation"]
"REGSHAVE" = "C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN" ["FUJI PHOTO FILM CO., LTD."]
"AOLDialer" = "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" ["America Online, Inc"]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"AOL Spyware Protection" = ""C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"" [null data]
"SpyHunter" = ** WARNING! empty or invalid data **
"SSC_UserPrompt" = "C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" ["Symantec Corporation"]
"TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{9ECB9560-04F9-4bbc-943D-298DDF1699E1}\(Default) = "CNisExtBho Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]
{AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = "Google Toolbar Helper" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]
{BDF3E430-B101-42AD-A544-FADC6B084872}\(Default) = "CNavExtBho Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {CLSID}\InProcServer32\(Default) = "C:\WINNT\System32\hticons.dll" ["Hilgraeve, Inc."]
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]
"{5464D816-CF16-4784-B9F3-75C0DB52B499}" = "Yahoo! Mail"
-> {CLSID}\InProcServer32\(Default) = "C:\WINNT\Downloaded Program Files\ymmapi.dll" ["Yahoo! Inc."]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\shellhook.dll" ["TODO: <Firmenname>"]
HKLM\Software\Classes\PROTOCOLS\Filter\
INFECTION WARNING! text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]
Enabled Screen Saver:
---------------------
HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "(NONE)" [file not found]
Enabled Wallpaper and Active Desktop:
-------------------------------------
Active Desktop is enabled.
Startup items in "Administrator" & "All Users" startup folders:
---------------------------------------------------------------
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"AOL Companion" -> shortcut to: "C:\Program Files\AOL Companion\companion.exe /s" [null data]
"AOL Tray Icon" -> shortcut to: "C:\Program Files\AOL 9.0\aoltray.exe -check" ["America Online, Inc."]
"Exif Launcher" -> shortcut to: "C:\Program Files\FinePixViewer\QuickDCF.exe" ["FUJI PHOTO FILM CO., LTD."]
"WinZip Quick Pick" -> shortcut to: "C:\Program Files\WinZip\WZQKPICK.EXE" ["WinZip Computing, Inc."]
Enabled Scheduled Tasks:
------------------------
"Norton AntiVirus - Scan my computer - Administrator" -> launches: "C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe /task:"C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\mycomp.sca"" ["Symantec Corporation"]
"Symantec NetDetect" -> launches: "C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE" ["Symantec Corporation"]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\rnr20.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\msafd.dll [MS], 01 - 03, 06 - 15
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
-> {CLSID}\(Default) = "&Google"
-> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
-> {CLSID}\(Default) = "&Google"
-> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}"
-> {CLSID}\(Default) = "Web assistant"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
-> {CLSID}\(Default) = "Norton AntiVirus"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}"
-> {CLSID}\(Default) = "Web assistant"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
-> {CLSID}\(Default) = "Norton AntiVirus"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
-> {CLSID}\(Default) = "&Google"
-> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]
Explorer Bars
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
{FE54FA40-D68C-11D2-98FA-00C0F0318AFE}\
-> {CLSID}\(Default) = "Real.com"
-> {CLSID}\InProcServer32\(Default) = "C:\WINNT\System32\Shdocvw.dll" [MS]
Dormant Explorer Bars in "View, Explorer Bar" menu
HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\
(Default) = "&Research"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
"ButtonText" = "Research"
{CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\
"ButtonText" = "Real.com"
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
AOL Connectivity Service, AOL ACS, "C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe" ["America Online, Inc."]
ewido security suite control, ewido security suite control, "C:\Program Files\ewido\security suite\ewidoctrl.exe" ["ewido networks"]
ewido security suite guard, ewido security suite guard, "C:\Program Files\ewido\security suite\ewidoguard.exe" ["ewido networks"]
MSSQL$MICROSOFTBCM, MSSQL$MICROSOFTBCM, "C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe -sMICROSOFTBCM" [MS]
Symantec Core LC, Symantec Core LC, "C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe" ["Symantec Corporation"]
Symantec Event Manager, ccEvtMgr, ""C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"" ["Symantec Corporation"]
Symantec Network Drivers Service, SNDSrvc, "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe" ["Symantec Corporation"]
Symantec Network Proxy, ccProxy, ""C:\Program Files\Common Files\Symantec Shared\ccProxy.exe"" ["Symantec Corporation"]
Symantec Settings Manager, ccSetMgr, ""C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"" ["Symantec Corporation"]
----------
This report excludes default entries except where indicated.
To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
----------
HJT
StartupList report, 5/8/2005, 7:14:17 PM
StartupList version: 1.52.2
Started from : C:\Program Files\HJT\HijackThis.EXE
Detected: Windows 2000 SP3 (WinNT 5.00.2195)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\System32\internat.exe
C:\Program Files\AOL Companion\companion.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\system32\NOTEPAD.EXE
C:\WINNT\System32\wuauclt.exe
C:\Program Files\HJT\HijackThis.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\Administrator\Start Menu\Programs\Startup]
*No files*
Shell folders AltStartup:
*Folder not found*
User shell folders Startup:
*Folder not found*
User shell folders AltStartup:
*Folder not found*
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
AOL Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
Shell folders Common AltStartup:
*Folder not found*
User shell folders Common Startup:
*Folder not found*
User shell folders Alternate Common Startup:
*Folder not found*
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINNT\system32\userinit.exe,
[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*
[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Synchronization Manager = mobsync.exe /logon
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
URLLSTCK.exe = C:\Program Files\Norton Internet Security\UrlLstCk.exe
REGSHAVE = C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
AOLDialer = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
AOL Spyware Protection = "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
SpyHunter =
SSC_UserPrompt = C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
internat.exe = internat.exe
wymrvfy = c:\winnt\ohrxdnu.exe
hesakcb = c:\winnt\ohrxdnu.exe
ydvxcka = c:\winnt\ohrxdnu.exe
bspjlog = c:\winnt\ohrxdnu.exe
avqdivq = c:\winnt\ohrxdnu.exe
hkokhoj = c:\winnt\ohrxdnu.exe
ywpenwu = c:\winnt\ohrxdnu.exe
sujqtiv = c:\winnt\ohrxdnu.exe
eqdolgd = c:\winnt\ohrxdnu.exe
kkuqlgl = c:\winnt\ohrxdnu.exe
ubmndea = c:\winnt\ohrxdnu.exe
oiqdlto = c:\winnt\ohrxdnu.exe
erfpphm = c:\winnt\ohrxdnu.exe
mpmgqvd = c:\winnt\ohrxdnu.exe
wjxowql = c:\winnt\ohrxdnu.exe
umyagtg = c:\winnt\ohrxdnu.exe
fcbmsce = c:\winnt\ohrxdnu.exe
pakynre = c:\winnt\ohrxdnu.exe
qvuufop = c:\winnt\ohrxdnu.exe
mxmshow = c:\winnt\ohrxdnu.exe
nptykyg = c:\winnt\ohrxdnu.exe
icmvgda = c:\winnt\ohrxdnu.exe
caqmvwi = c:\winnt\kadtfeo.exe
ikihvdc = c:\winnt\kadtfeo.exe
hewqaos = c:\winnt\kadtfeo.exe
pswrdvo = c:\winnt\kadtfeo.exe
snhfutt = c:\winnt\kadtfeo.exe
jjxgtvm = c:\winnt\kadtfeo.exe
vtpdses = c:\winnt\kadtfeo.exe
bsgjfye = c:\winnt\kadtfeo.exe
udqxvbl = c:\winnt\kadtfeo.exe
hitasut = c:\winnt\cnurihq.exe
jmesujl = c:\winnt\cnurihq.exe
jgutffg = c:\winnt\cnurihq.exe
teltnsp = c:\winnt\cnurihq.exe
owurqis = c:\winnt\cnurihq.exe
qusxoeo = c:\winnt\cnurihq.exe
hkrttta = c:\winnt\cnurihq.exe
qskudot = c:\winnt\cnurihq.exe
pbjitog = c:\winnt\cnurihq.exe
midmbwv = c:\winnt\cnurihq.exe
fhrfkxp = c:\winnt\cnurihq.exe
oaiaedw = c:\winnt\cnurihq.exe
vvdlmjc = c:\winnt\cnurihq.exe
rnvwyba = c:\winnt\cnurihq.exe
ojmpnwk = c:\winnt\cnurihq.exe
hbsfrhw = c:\winnt\cnurihq.exe
gggggxo = c:\winnt\cnurihq.exe
huqcsgj = c:\winnt\cnurihq.exe
irrccpu = c:\winnt\cnurihq.exe
uwjvnln = c:\winnt\cnurihq.exe
epsrjti = c:\winnt\mwiswfo.exe
ffihdnc = c:\winnt\mwiswfo.exe
oohanrj = c:\winnt\mwiswfo.exe
gisvghe = c:\winnt\mwiswfo.exe
jusdyqg = c:\winnt\mwiswfo.exe
ukohfei = c:\winnt\mwiswfo.exe
tupyrsn = c:\winnt\mwiswfo.exe
drasegk = c:\winnt\mwiswfo.exe
tradkou = c:\winnt\mwiswfo.exe
yccsets = c:\winnt\mwiswfo.exe
iwlbnvs = c:\winnt\mwiswfo.exe
vxslbei = c:\winnt\mwiswfo.exe
bitkaqt = c:\winnt\mwiswfo.exe
bwuykvd = c:\winnt\mwiswfo.exe
cfkixgk = c:\winnt\mwiswfo.exe
xsqqpoq = c:\winnt\mwiswfo.exe
thbfpfl = c:\winnt\mwiswfo.exe
kibuwdc = c:\winnt\mwiswfo.exe
fsqowsf = c:\winnt\mwiswfo.exe
evedfyu = c:\winnt\mwiswfo.exe
jlyotdv = c:\winnt\mwiswfo.exe
efvahem = c:\winnt\mwiswfo.exe
owccmuo = c:\winnt\mwiswfo.exe
miivuet = c:\winnt\mwiswfo.exe
wkekaan = c:\winnt\mwiswfo.exe
qgssfdo = c:\winnt\mwiswfo.exe
vcevdfm = c:\winnt\mwiswfo.exe
nxptycu = c:\winnt\mwiswfo.exe
oqsbtmi = c:\winnt\mwiswfo.exe
ppkcjsk = c:\winnt\mwiswfo.exe
qqvqiws = c:\winnt\mwiswfo.exe
hkqefaf = c:\winnt\mwiswfo.exe
dxeoely = c:\winnt\mwiswfo.exe
pnitcho = c:\winnt\mwiswfo.exe
arrgjre = c:\winnt\mwiswfo.exe
ealmrwc = c:\winnt\mwiswfo.exe
cpbglvh = c:\winnt\mwiswfo.exe
sderaly = c:\winnt\mwiswfo.exe
ixuotoq = c:\winnt\mwiswfo.exe
gxxvlnf = c:\winnt\mwiswfo.exe
pdocqpn = c:\winnt\mwiswfo.exe
jdrqpmh = c:\winnt\mwiswfo.exe
irldsix = c:\winnt\mwiswfo.exe
evpbhwi = c:\winnt\mwiswfo.exe
kmukorg = c:\winnt\mwiswfo.exe
yqwjghr = c:\winnt\mwiswfo.exe
tdkibxe = c:\winnt\mwiswfo.exe
uqwcupk = c:\winnt\mwiswfo.exe
fxupxlb = c:\winnt\mwiswfo.exe
ffryjpl = c:\winnt\mwiswfo.exe
aamwhmn = c:\winnt\mwiswfo.exe
vagjdka = c:\winnt\mwiswfo.exe
llqqdhj = c:\winnt\mwiswfo.exe
afcwccw = c:\winnt\imujmni.exe
rpekvgf = c:\winnt\imujmni.exe
oihmkve = c:\winnt\imujmni.exe
gnhpayx = c:\winnt\imujmni.exe
whlinpb = c:\winnt\imujmni.exe
dsfsofp = c:\winnt\imujmni.exe
hijxopg = c:\winnt\imujmni.exe
oscuxms = c:\winnt\imujmni.exe
lpihaxe = c:\winnt\imujmni.exe
vysgsjv = c:\winnt\imujmni.exe
nmsgloc = c:\winnt\imujmni.exe
qwobeto = c:\winnt\imujmni.exe
bhjdena = c:\winnt\imujmni.exe
eirpatk = c:\winnt\imujmni.exe
mrbqxia = c:\winnt\imujmni.exe
hxkiejj = c:\winnt\imujmni.exe
pirjqon = c:\winnt\imujmni.exe
mdhfpkf = c:\winnt\imujmni.exe
wutvhqw = c:\winnt\imujmni.exe
hoowwkq = c:\winnt\imujmni.exe
eiwodod = c:\winnt\imujmni.exe
qhiboty = c:\winnt\imujmni.exe
inslqeq = c:\winnt\imujmni.exe
jgwkkwj = c:\winnt\imujmni.exe
orvtosm = c:\winnt\imujmni.exe
wbmhbtg = c:\winnt\imujmni.exe
chrohsl = c:\winnt\imujmni.exe
amuklml = c:\winnt\imujmni.exe
rflurmo = c:\winnt\imujmni.exe
vgfgnjm = c:\winnt\imujmni.exe
hlrhbao = c:\winnt\imujmni.exe
wfsdpsf = c:\winnt\imujmni.exe
xmcoxwd = c:\winnt\imujmni.exe
jdwxouv = c:\winnt\imujmni.exe
xeemdag = c:\winnt\imujmni.exe
khkiefh = c:\winnt\imujmni.exe
yvtompe = c:\winnt\imujmni.exe
tbcflen = c:\winnt\imujmni.exe
ysulbxi = c:\winnt\imujmni.exe
tpamgwd = c:\winnt\imujmni.exe
uoohbgi = c:\winnt\imujmni.exe
oboluvm = c:\winnt\imujmni.exe
amkqjqn = c:\winnt\imujmni.exe
ygxgiid = c:\winnt\imujmni.exe
fbcwgnt = c:\winnt\imujmni.exe
gwdvyel = c:\winnt\imujmni.exe
ulmnxsv = c:\winnt\imujmni.exe
uiodpbx = c:\winnt\imujmni.exe
jeotdpd = c:\winnt\imujmni.exe
oryhxba = c:\winnt\imujmni.exe
qhlpjcl = c:\winnt\imujmni.exe
ihxynbh = c:\winnt\imujmni.exe
ypfgilf = c:\winnt\imujmni.exe
denqjrj = c:\winnt\imujmni.exe
pcafyfo = c:\winnt\imujmni.exe
gfrqsgq = c:\winnt\imujmni.exe
njqhyln = c:\winnt\imujmni.exe
cgjumje = c:\winnt\imujmni.exe
ljdsurf = c:\winnt\imujmni.exe
kwrxybb = c:\winnt\imujmni.exe
yaxioqp = c:\winnt\imujmni.exe
mlkbmhs = c:\winnt\imujmni.exe
kysmeto = c:\winnt\imujmni.exe
oiqbvwd = c:\winnt\imujmni.exe
rntgpqb = c:\winnt\imujmni.exe
qvrixmm = c:\winnt\imujmni.exe
ajmakbk = c:\winnt\imujmni.exe
paavjfn = c:\winnt\imujmni.exe
axeuyjp = c:\winnt\bghxjvw.exe
wpjixev = c:\winnt\bghxjvw.exe
pnwcjom = c:\winnt\bghxjvw.exe
iviavgl = c:\winnt\bghxjvw.exe
ramibwu = c:\winnt\bghxjvw.exe
oxrebmb = c:\winnt\bghxjvw.exe
osonrdl = c:\winnt\bghxjvw.exe
ajpcfpt = c:\winnt\bghxjvw.exe
nbbonej = c:\winnt\bghxjvw.exe
shyrsia = c:\winnt\bghxjvw.exe
ayfgydw = c:\winnt\bghxjvw.exe
shvmuhe = c:\winnt\bghxjvw.exe
ixdtnen = c:\winnt\bghxjvw.exe
njectjw = c:\winnt\bghxjvw.exe
hfvlbjo = c:\winnt\bghxjvw.exe
khhtxlj = c:\winnt\bghxjvw.exe
ramyspf = c:\winnt\bghxjvw.exe
jsjvfef = c:\winnt\bghxjvw.exe
yjfdygd = c:\winnt\bghxjvw.exe
ytlsqwl = c:\winnt\bghxjvw.exe
lrvctym = c:\winnt\bghxjvw.exe
ptacsln = c:\winnt\bghxjvw.exe
wxhtffd = c:\winnt\bghxjvw.exe
ixkggsa = c:\winnt\bghxjvw.exe
eohpqwk = c:\winnt\bghxjvw.exe
gvvhbqu = c:\winnt\bghxjvw.exe
udayxsp = c:\winnt\bghxjvw.exe
dnmsbcw = c:\winnt\bghxjvw.exe
cemsnpb = c:\winnt\bghxjvw.exe
yxnxslo = c:\winnt\bqeqaso.exe
hrggukd = c:\winnt\bqeqaso.exe
dhgwqyp = c:\winnt\bqeqaso.exe
fvasaid = c:\winnt\bqeqaso.exe
hnkqnsd = c:\winnt\bqeqaso.exe
rknevxu = c:\winnt\bqeqaso.exe
nftagqo = c:\winnt\bqeqaso.exe
iiddptl = c:\winnt\bqeqaso.exe
cyefhug = c:\winnt\bqeqaso.exe
nccemra = c:\winnt\bqeqaso.exe
lxnrooy = c:\winnt\bqeqaso.exe
fmcwfkq = c:\winnt\bqeqaso.exe
enqkyeq = c:\winnt\bqeqaso.exe
fjekmkd = c:\winnt\bqeqaso.exe
lwqcotb = c:\winnt\bqeqaso.exe
uqbcovj = c:\winnt\bqeqaso.exe
mgxsvch = c:\winnt\bqeqaso.exe
cvuqaey = c:\winnt\bqeqaso.exe
orvetwg = c:\winnt\bqeqaso.exe
sjudger = c:\winnt\bqeqaso.exe
sjpsouo = c:\winnt\bqeqaso.exe
dtqflrv = c:\winnt\umetjwa.exe
qqpiptd = c:\winnt\wbednct.exe
fvimgni = c:\winnt\ejounne.exe
dfrkged = c:\winnt\umetjwa.exe
djhtbnv = c:\winnt\wbednct.exe
ucjnhnx = c:\winnt\ejounne.exe
qqvrspj = c:\winnt\wbednct.exe
rkkubkc = c:\winnt\umetjwa.exe
rehlsww = c:\winnt\ejounne.exe
nmfhyhl = c:\winnt\wbednct.exe
rlschev = c:\winnt\umetjwa.exe
krfsrhy = c:\winnt\wbednct.exe
xcluqra = c:\winnt\umetjwa.exe
xlwmeij = c:\winnt\wbednct.exe
jgrsahx = c:\winnt\umetjwa.exe
qjfpjbr = c:\winnt\wbednct.exe
iaylofm = c:\winnt\umetjwa.exe
sgsfqaw = c:\winnt\vixwkwk.exe
rjeniur = c:\winnt\vixwkwk.exe
plbiyiv = c:\winnt\vixwkwk.exe
aejqtjp = c:\winnt\vixwkwk.exe
knneiyb = c:\winnt\vixwkwk.exe
fmyeurc = c:\winnt\vixwkwk.exe
dpyujba = c:\winnt\vixwkwk.exe
jhnbqus = c:\winnt\vixwkwk.exe
filddik = c:\winnt\vixwkwk.exe
ayelfgb = c:\winnt\vixwkwk.exe
tqutdfw = c:\winnt\vixwkwk.exe
iygbtor = c:\winnt\vixwkwk.exe
lluvtqb = c:\winnt\vixwkwk.exe
nycaakt = c:\winnt\vixwkwk.exe
gmouinj = c:\winnt\vixwkwk.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No values found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[OptionalComponents]
*No values found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*
--------------------------------------------------
File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command
(Default) = "%1" %*
--------------------------------------------------
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command
(Default) = "%1" /S
--------------------------------------------------
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command
(Default) = C:\WINNT\System32\mshta.exe "%1" %*
--------------------------------------------------
File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1
--------------------------------------------------
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)
[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = "C:\WINNT\System32\shmgrate.exe" OCInstallUserConfigIE
[>{6D673AA6-C360-4AAC-8413-A284A257EA90}] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = "C:\WINNT\System32\shmgrate.exe" OCInstallUserConfigOE
[{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\mplayer2.inf,PerUserStub.NT
[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
[{6A5110B5-E14B-4268-A065-EF89FF33C325}] *
StubPath = regsvr32.exe /s /n /i:"S 2 true 3 true 4 true 5 true 6 true 7 true" initpki.dll
[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\wmp.inf,PerUserStub
[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll
[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\System32\ie4uinit.exe
[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINNT\System32\Rundll32.exe C:\WINNT\System32\mscories.dll,Install
[{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
StubPath = %SystemRoot%\System32\updcrl.exe -e -u %SystemRoot%\System32\verisignpub1.crl
--------------------------------------------------
Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps
*Registry key not found*
--------------------------------------------------
Load/Run keys from C:\WINNT\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=
------------